|
Trojan.Java.Nochea Viruses Information
| Name: |
Trojan.Java.Nochea |
| Category: |
Viruses |
| Description:
|
Details
Trojan.Java.Nocheat
Java.Nocheat is a Trojan program written in the Java programing language. It makes it possible to alter the system registry and files on victim computers.
The program contains four files:
Count.class
Dummy.class
nocheat.class
ok.class
Count.class - size 20686 bytes. It loads the class files "nocheat.class" and executes its function Init. This program component uses an Exploit to Virtual Java Machine. The file "nocheat.class" will have access local files and the system registry.
Dummy.class - size 235 bytes. It contains the void function and variable under the name: URLClassLoader.
nocheat.class - size is 6518 bytes. This is the main component of the Trojan program and can execute several commands on a local computer. The commands are: - The "HP" command -
Changes the start page of Internet Explorer
- The "SS" command -
Adds athe following string to the system registry key:
"\Internet Settings\SafeSites"
- The "HST" command -
Adds a string to the "hosts" file in the directory:
system32driversetc
- The "FV" command -
Creates the ".url" file into the filder "Favorites" for a current user.
- The "DT" command -
Creates a ".url" file in the "Desktop" folder of the current user.
- The "SP" command -
Changes the system registry keys:
"Internet Explorer", "SearchURL"
"Internet Explorer\Main", "Use Custom Search URL"
"Internet Explorer\Main", "Search Page"
"Internet Explorer\Main", "Search Bar"
"Internet Explorer\Search", "SearchAssistant"
"Internet Explorer\Search", "CustomizeSearch"
"Internet Explorer\Main", "Default_Search_URL"
"Internet Explorer\Main", "Search Page"
"Internet Explorer\Search", "SearchAssistant"
ok.class - size 996 bytes. Contains the functions of "myDefineClass" and "loadClass". |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Explosio
Natas.498
Trojan.Win32.Prondir.
10past3.
Dos7.34
Macro.Word.Mot
Macro.Word.Parasite (Concept.g,
NextGen.230
Spanz.63
Trojan-Spy.HTML.Bankfraud.j
|